
Google is expected to introduce full access permissions for Gemini that would allow it to access any file on a macOS device, open apps, browse the web, and perform actions without asking for permission every time.
As spotted by AI news tracker , the permission has been included in a new "Additional sandbox options" setting.
It allows Gemini to read, create, modify, or delete files residing anywhere on a Mac, including files outside connected folders and even files belonging to other people stored on the device.
Notably, it could also communicate with other Mac applications such as Mail, Safari, or Messages, and carry out actions through them without specific permission.
"Gemini will still ask user permission before purchasing products, creating accounts, accepting legal terms, or modifying sensitive information about you," the report reads.
The news highlights the lengths to which vendors will go to gain access to high-quality, up-to-date and unique AI training data, according to Ilia Kolochenko, founder of ImmuniWeb.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"Today, 99% of websites, online archives and web libraries have erected technical barriers to ban AI data scrapers, leaving AI vendors without access to free data,” he said.
“We will almost certainly see all major AI companies following Google and collecting their AI training data via various 'creative' techniques.”
Kolochenko added that access to training data is an “existential question for all Ai vendors,” but most will “probably accept the risk”.
The situation is even riskier for smaller vendors, he noted, many of whom are limited by funds and other resources to procure training data for in-house AI models.
"They form the so-called AI training pools, where hundreds of smaller players submit some data and, in exchange, can use all other data from the pool," he said. "Eventually, once you share your data with a small AI startup, it may end up in thousands of wrong hands around the globe."
The news comes as Apple tightens up Mac security for AI agents, announcing plans to introduce additional controls that will require Mac users to take "very explicit" action to enable Full Disk Access.
"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems —including files, mail, messages, and even browsing history —without users’ full knowledge and understanding," said the firm.
"Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action."
The new Gemini feature hasn't yet been enabled, and it's not clear when Google might plan to do so.
approached Google for comment, but did not receive a response by time of publication.